00:45
0

How to Remove a Virus Using Command Prompt?

www.hackoooo.blogspot.in


  • Go to start  menu and type “cmd” in search box or Start>all programs>accessories>command prompt.
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgZsGdA53CeyjaaNhmvt89sOJeXhI7tD2xuUFTZsh273zuf2Ib9vlKc8Jy0I3PNCQ_FMpomfprnA-rS0rBRB_XqxvpuJskM9WIPSiuUT7QDrPKijt2QRHNh2SUfcgxbZY_tdaHMoAtn2bs/s1600/g.png
  • Open the infected drive such as write , g: to go to G drive.
  • Now type dir/w/a . It will show all the files of the drive including hidden files.
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjK4uYc4B2-ngfYjlHcBypkzR_fq8iWSsk1aEQ5a0MtBsl3SlfwiZl-gncwn0CWCqyJjovPxXfzhtVzaS3ZFJeGTnDpxVm3r4NOwwq9x9iREHstuvln_ktbKpAfHVaH3fnjGfuhTZVlE6I/s1600/d1.png
  • Locate AUTORUN.INF or any Virus and other suspicious files in the directory.
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgtmc26VQayG4t6wJxAs8cY2Gp_G6MMgBYkz4ipkKHu-o05flP8VYmSyKreIC91RtNFoUEG1XikZkt3kCbOFZDLAmpaApcAUIyJlL3B2TnoGEe5NDlTus9jPt-SSuujiMbn4Sq4MmStaBI/s1600/autorun.png
there was no virus in my drive so only autorun.inf is been highlighted.
  • Type command attrib  -r –a –s –h to remove attributes of corresponding file.
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjkoySKeyperWE1tNNM8cBMdxEnOKM4C2czfbrosgdH0Lv6Ka0wkUtL_sGNGRzUCYRhIAr6GNHPRkNk28WV2QFNp6fcLCxg44uXmcM_-VOsyZm-3kk6TRR6XjObmL8IhYnDVmg7CasbAjs/s1600/ra.png
Type del autorun.inf to delete autorun.inf file.
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjoJgEruakFLA_qh5OsODVs1YbyAaH9lrNhV1aMLeVLl1fkmwNQA4Jwg-_lOK9ofYJ03rkXkOe0qo31Qscnmyd_nw6bMG_Vf-jnjpcsX86K7qk9P06rPswa2PL0nNjofLOHjjjWRhOMS8o/s1600/dar.png
  • Now type del virus name.exe t delete it, eg : del newfolder.exe .
(You can also delete viruses by using following steps:
  • When you find an Autorun.inf file or any other unusual .exe file just rename it.
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg0JAJdEY0YiYgc_-l53vlV_nbYSrQf_ZgNXALGD3UE0O-9M6nIfncNMYDFO5U7eR6v3hwBbwB4x3R-M0x8_9t8MZHcFDMo5ZOiG9e7SzGGPR6EC0BgV9x_uVEpKB4Mf-q7P6qh-cNhZ4I/s1600/Capture1.png
Syntax for rename is (rename filename.extension new name ,  for example: (rename autorun.inf virus) to rename autorun.inf file. Here I have renamed it by “virus”.
  • Now you can access the defected drive without affecting the virus.
  • To delete the renamed file go to the defected drive and select file you renamed.
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiNM_XQElTXRVSml7FFVyYtN7Lx-509PxlfN7lwS0uHNRhFxgSH6lkzM_M-9XNfS2jxOsOSENQw19WljYX70v1O2L4mFVBxIdg68SoPsHC588aF-YjJRDyycRoicu2dAG9O3__oAJJTJaA/s1600/delvirus.png
Now delete the harmful renamed files. You have deleted that virus successfully but sometimes virus resides in the Recycler folder.To locate this folder:
  • Type cd recycler command.
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiBwFjdavGdSdy6z1Kl1xoyvW59XjaPpcOnXIAAvuZYtYBkHU10DHoIviaIVIyJl8XJARW6cFYOx1fs7ZEUGRe1aA9mqq1beEyCnvRZ-LPsD2SjnST4riG344LPrK6eJoX8Qz2eTm29a7E/s1600/cr.png
  • Again type dir/w/a  to locate all file of the folder.
  • Identify malicious files and delete them using above commands.
Follow the above steps carefully and i think this information is enough to remove a virus using command prompt easily.
Important: Make sure that no other processes being running while performing these actions. 

0 comments:

Contact me

Name

Email *

Message *